HNHacker News
TopNewBestAskShowJobs

csandreasen

719 karma · joined March 26, 2011

submissionscomments
csandreasen··on New Emails in Clinton Case Came from Anthony Weiner’s Electronic Devices
Don't apologize - factcheck.org is right; thehill.com is wrong. Just go back to the original FBI report here:[1]. None of the e-mails were properly marked; three e-mails chains consisting of eight individual messages had at least one paragraph marked with a (C), but no header, footer, other portion marks, etc. to indicate classification. The content of two of those e-mail chains were determined to be unclassified based on current classification guidance.

There were 81 e-mail chains from her server that should have been marked as classified because they contained classified information (and thus shouldn't have been sent over unclassified e-mail). Quite a few outlets have made the mistake of conflating being marked as classified with containing classified information. The thehill.com article links to another article using the phrase 'Twenty-two emails in eight different chains of messages were [marked as top secret]', but the article they link to says 'The Obama administration will entirely withhold 22 emails from Hillary Clinton’s private server because they have been classified as “top secret,”...'.

The point of classification markings is to unambiguously identify that the document contains classified information, what parts are classified and how to protect it. If it's not marked as such, there's the possibility that the recipient(s) won't realize that there's classified information in it. The most likely reason that the e-mails with classified information were sent in the first place was most likely that the sender didn't realize that the information was classified, or there might be differences in opinion between multiple government organizations as to whether a particular is classified or to what degree it is classified. An example is drone strikes in Pakistan and Yemen - according to CIA that information is classified, but you could read about it in the newspapers.

Based on the description from factcheck.org, I was able to find two of e-mails with the (C) portion marks: [2],[3] Note that [3] was not redacted because it was classified, but rather due to FOIA exemption (you can see that everything after the (C) was left unredacted). [2] was redacted on account of both containing confidential information in the last paragraph as well as FOIA exemption.

[1] https://vault.fbi.gov/hillary-r.-clinton/hillary-r.-clinton-... (page 20)

[2] http://graphics.wsj.com/hillary-clinton-email-documents/pdfs...

[3] http://graphics.wsj.com/hillary-clinton-email-documents/pdfs...

csandreasen··on Chinese hacked CNN (sportsillustrated.cnn.com)
This is an installation banner, as in: "You've successfully installed LNMP"

From the LNMP GitHub page:

This script is written using the shell, in order to quickly deployLEMP/LAMP/LNMP/LNMPA(Linux, Nginx/Tengine/OpenResty, MySQL in a production environment/MariaDB/Percona, PHP), applicable to CentOS 5~7(including redhat), Debian 6~8, Ubuntu 12~15 of 32 and 64.

https://github.com/lj2007331/lnmp

csandreasen··on In Silicon Valley, a new emphasis on barriers to government requests for data
CNN and the Washington Post both reported that WhatsApp and Telegram were found on several of the Paris attackers' phones, but that the content wasn't able to be recovered.

http://www.cnn.com/2015/12/17/politics/paris-attacks-terrori...

https://www.washingtonpost.com/world/europe/paris-attack-pla...

csandreasen··on Hidden Microphones Part of Government Surveillance Program in the Bay Area
From your link:

(c) The term “confidential communication” includes any communication carried on in circumstances as may reasonably indicate that any party to the communication desires it to be confined to the parties thereto, but excludes a communication made in a public gathering or in any legislative, judicial, executive or administrative proceeding open to the public, or in any other circumstance in which the parties to the communication may reasonably expect that the communication may be overheard or recorded.

csandreasen··on Tor exit node operator gets raided by police
Absolutely. If a business is offering services that a customer is using to commit a crime, the police wouldn't be doing their jobs if they didn't go down and ask for logs.
csandreasen··on The Next Front in the New Crypto Wars: WhatsApp
That's interesting. They've come pretty close to that line in the past...

https://www.eff.org/deeplinks/2014/04/tea-party-taxes-and-wh...

csandreasen··on Brazil arrests Facebook executive in row over police access to data
Probably about as much as you see from him on the subject of Russia and China. The Intercept is about as unbiased as Fox News - lots of criticism directed towards the US and its allies, silence on every other country.
csandreasen··on Justice Department Wants Data from About 12 Other iPhones
A gaping "backdoor" already exists in the form of the software update mechanism. By the same logic you're using, Apple can't keep their source code and signing key secure forever, which would be a much worse leak than them losing control of a modified iOS that would let someone brute force a PIN for a phone in their physical possession without the phone being wiped.
csandreasen··on Justice Department Calls Apple’s Refusal to Unlock iPhone a ‘Marketing Strategy’
This is more like the FBI asking the storage unit owner to turn off the security system that he installed that incinerates the contents of the storage unit when someone tries to pick the lock, but only on the unit that the FBI has a warrant to search. The storage unit owner then responds that although he could put an off switch on that particular unit, it's an outrage and sets a horrible precedent that the police should ever ask him to turn off his security incinerator.
csandreasen··on Why Apple Is Right to Challenge an Order to Help the F.B.I
By that same logic, Apple's source code and software update key could eventually leak, too, which would have even worse effect. The FBI is handing the phone over to Apple to apply the modification, not asking Apple to them the means to do it themselves. If Apple was really worried about this leaking, they could just delete it when they're done (though it would be more work for them to recreate it next time the FBI comes with a warrant to search another iPhone).
csandreasen··on U.S. can't ban encryption because it's a global phenomenon, Harvard study finds
Demanding keys would conflict with the 5th Amendment; in the few cases that I'm aware of[1][2] where a defendant was successfully compelled to decrypt their files, the suspect had either already demonstrated that the evidence was in their possession and thus given up their right to self- incriminate or been granted immunity. Also, with end-to-end encryption law enforcement won't be able to decrypt regardless of whether or not they have a warrant, and they need a warrant to initiate a wiretap to begin with.

[1] https://news.ycombinator.com/item?id=9663447

[2] https://news.ycombinator.com/item?id=9663378

csandreasen··on U.S. can't ban encryption because it's a global phenomenon, Harvard study finds
I don't think that's an appropriate analogy. You may as well just say "In the 1700s, if you wrote an enciphered letter..." since cryptography isn't a new concept. Various schemes have been used to protect military and diplomatic communications for centuries. If you did so then or now, you wouldn't be under any obligation to reveal the contents, but you take on the additional burden of actually performing all of the necessary calculations, securely destroying the scratch paper you used in the process of encrypting the message, handling key management and distribution, securing the areas where the encrypting/decrypting is taking place (you wouldn't want the redcoats barging in the hour or so while you're in the middle of converting the plaintext to ciphertext), etc.

Nobody does that anymore. You're instead using a tool that someone else made, and either that tool or the other person is handling all of the hard work. Tools definitely can be regulated - I need a license to drive; I need to register my car; I need to go through a background check to own a gun; I can own a gun, but if I misuse it I go to jail; felons can't purchase guns legally; I can't buy a nuclear weapon or the fissile material needed to make own.

The questions that policymakers are fumbling through right now are things like "how (if at all) do we regulate tools and the companies that make/distribute them if those tools allow people evade law enforcement?"

csandreasen··on Denmark confirms US sent rendition flight for Snowden
First off, Martin Luthor King didn't kill himself, so you can't really say that the FBI compelled him to do so.

Secondly, you're using the actions taken by a domestic law enforcement agency more than half a century ago as evidence that a foreign intelligence agency is going to blackmail Americans, neglecting the difference in missions between the two agencies, the changes in legal authorities since the 60s, the fact that multiple generations of Americans with differing cultural values have come into and left government service, etc.

Thirdly, calling someone ignorant is an insult. I'd suggest consulting the forum guidelines linked at the bottom of the page.

csandreasen··on Denmark confirms US sent rendition flight for Snowden
> Anyone who intends subversive action can be targetted. They can be approached and manipulated by an agent who knows everything about them. The would-be-subversive can be nudged, sabotaged or flat out blackmailed.

You've just highlighted why the average American is scared of terrorists but not the NSA: 3000 people did die on 9/11. There is no evidence of the NSA targeting Americans, or nudging/sabotaging/blackmailing them.

The military could easily storm Washington DC, topple the government, execute every Congressman, impose martial law and announce the start of a new regime under the sole authority of the Chairman of the Joint Chiefs of Staff. You'd have to be pretty nuts to worry that's actually going to happen.

Also, referring to people who disagree with you as ignorant isn't generally the best way to change their minds.

csandreasen··on Denmark confirms US sent rendition flight for Snowden
> The US government revoked his passport while he was in an international "no man's land" (i.e. the international side of Russian customs), effectively making him stateless.

This is a myth that keeps getting repeated. The US government didn't revoke his passport leaving him stranded in Russia, they revoked his passport the day before he left Hong Kong [1]. He traveled to Russia on what turned out to be an invalid travel document issued by the Ecuadorian embassy in London [2] (same one that Julian Assange is holed up in).

He was allowed by the Chinese to flee from a place that had an extradition treaty with the US and wound up in a place that doesn't. He put himself there. Honestly, the "It's the American government's fault I'm in Russia" argument that Snowden and his close supporters have been peddling isn't really much of an argument when it effectively translates to "If it weren't for the US government I'd be in Cuba or Ecuador right now."

> Also worth noting that the crimes Snowden has been charged with are two counts of violating the Espionage Act, a law passed just after the US entered WWI.

I keep seeing this argument being brought up, too. The age of a particular law has no impact on whether or not someone should be accountable for breaking it. If that were the case, I could quite literally get away with murder.

[1] http://bigstory.ap.org/article/ap-source-nsa-leaker-snowdens...

[2] http://www.theguardian.com/world/2013/jul/02/ecuador-rafael-...

csandreasen··on Shadowy tech brokers that deliver your data to the NSA
There's a huge difference between those links and showing systemic abuse. When I actually go and read the stories behind your links, what you state is that 13 people in 10 years abusing their position at the NSA to spy on their significant others (and subsequently being fired, resigning or being relieved of their positions[1]) is a stone's throw away from having a federal agent being assigned to watch me personally have intercourse. This says to me that the average American should be about as worried about being spied on by the NSA as they are worried about being struck by lightning on a clear day. The odds might go up slightly if they had a jealous ex working at the NSA.

I have better odds of getting shot by a government agent than being spied on, and I generally manage to get through my day without worrying that I'll die at the hands of the US government. I think that's probably the biggest reason that so few people outside of HN/Reddit/etc. care about Snowden leaks. I can find plenty of people that are upset about police brutality, and there's lots of discussion about implementing body cameras, discrimination in law enforcement, etc. because I can find new, documented evidence of someone getting shot by a cop every other week. It's still not at the level where I worry that I'm going to get shot by a cop. Snowden showed potential for abuse, not actual abuse. That's why "I have nothing to hide" persists.

[1] The source document for the LOVEINT stories (not linked from either of those articles) is https://www.nsa.gov/public_info/press_room/2013/grassley_let...

csandreasen··on Shadowy tech brokers that deliver your data to the NSA
To which I would ask "Under what circumstances would the government pay a federal agent to watch me have sex for the next 10 years?" This and the similar comparisons that I often see raised in response to the "I have nothing to hide" argument are ridiculous hypotheticals that are raised without taking into account who is violating the subject's privacy and why. When someone says "I have nothing to hide" it's generally short for "I have committed no crimes and I trust law enforcement officials to a) only invade someone's privacy when they have reasonable grounds (implying that they got a warrant); and b) use any data collected only in pursuit of actual criminal investigations (e.g. they're not going to steal my credit cards and broadcast naked pictures all over the internet).

If you're going to change people's minds with that argument, you need to be able to demonstrate that people's data is being routinely searched without just cause and/or police are routinely abusing the fruits of those searches.

csandreasen··on NSA Cheerleaders Discover Value of Privacy Only When Their Own Is Violated
To put this into perspective, it's worth noting that this was an issue of almost unprecedented contention between the US and Israel over whether or not to lift sanctions against Iran in exchange for nuclear disarmament. What Israel does to advance its foreign policy objectives is definitely within the purview of a foreign intelligence agency, and in this case the Israeli government was very actively lobbying congress. It seems pretty clear to me that the goal was to find out what Israel was doing, not spy on Congress.

The folks over at Lawfare had a much different breakdown of the issue: https://www.lawfareblog.com/why-do-conservatives-suddenly-so...

Relevant quote:

Was the activity properly disclosed to the intelligence committees? Actually, NSA’s behavior with respect to Israel appears to have been briefed to Congress, as one would hope. “Convinced Mr. Netanyahu would attack Iran without warning the White House, U.S. spy agencies ramped up their surveillance, with the assent of Democratic and Republican lawmakers serving on congressional intelligence committees” (emphasis added).

csandreasen··on Juniper hack has U.S. fearing foreign infiltration
If code was added to leak the state of the PRNG, then whether or not Dual EC is used becomes a non-issue. The person who created the backdoor could leak the state regardless of which PRNG was used.
csandreasen··on Juniper hack has U.S. fearing foreign infiltration
Is this guy sitting in a coffee shop with a 2U rackmount ScreenOS-based hardware VPN connected to his laptop? If not, this particular attack that the article is discussing wouldn't work.
csandreasen··on Juniper hack has U.S. fearing foreign infiltration
It's even more complicated than that - Juniper used Dual EC, and changed the Dual EC parameters, but ultimately the output of that PRNG was being used to seed a different PRNG (probably for speed purposes).

From your 2nd link:

ScreenOS does make use of the Dual_EC_DRBG standard, but is designed to not use Dual_EC_DRBG as its primary random number generator. ScreenOS uses it in a way that should not be vulnerable to the possible issue that has been brought to light. Instead of using the NIST recommended curve points it uses self-generated basis points and then takes the output as an input to FIPS/ANSI X.9.31 PRNG, which is the random number generator used in ScreenOS cryptographic operations.

Because of this, it's not entirely clear at this point that an attack would have been feasible even for an actor that had the P and Q used for Dual EC here[1].

[1] https://twitter.com/pwnallthethings/status/67837170536721203...

csandreasen··on The Moral Failure of Computer Scientists
If you're going to use the envelope analogy, also consider that we don't put our mail in envelopes to prevent the police from intercepting it; we put them in envelopes to prevent access by all of the people handling the mail between the sender and intended recipient. A cop with a warrant can rightly get access to a person's mail in transit. The envelope also isn't particularly difficult to get around - we don't secure our mail through technical measures but instead by putting stiff legal penalties on tampering with it.
csandreasen··on How not to report on the encryption ‘debate’
Forcing the terrorists/criminals to roll their own encryption would be a huge win for both law enforcement/foreign intelligence agencies and the general public. When non-cryptographers write their encryption software the likelihood that it's insecure goes up, and if they're off using Mujahideen Secrets v5.0 instead of WhatsApp their communications would stick out like a sore thumb instead of blending in with regular users. When the terrorists/etc. don't blend in, the FBI/NSA/etc. don't have to sift through mainstream communications channels to figure out which people are bad guys and which are just regular people.
csandreasen··on Open-source license plate reader
I'm not quite sure how generating more data about people's locations and putting it in the hands of more people is considered a victory for privacy advocates.
csandreasen··on Patriot Act author warns EU against dragnet response to terror
Jim Sensenbrenner is the last person who should be lecturing on dragnet surveillance. He was one of the writers of the PATRIOT Act, then failed to attend any classified briefings where the NSA explained what they were doing with the phone records program. He later went on to admit that he didn't attend them because didn't want to have to deal with the burden of handling classified information[2]. He had at least six opportunities to hear exactly what was going on, voice his dissent and put forth legislation to curtail it. Instead he put the laws into place then shirked his duty to provide any oversight, somehow proud of the fact that he was legislating from a position of willful ignorance. That kind of behavior is exactly what the EU should be warned about.

[1] http://www.msnbc.com/msnbc/patriot-act-architect-cries-foul-...

[2] https://www.lawfareblog.com/shameless-revisionism-james-sens...

csandreasen··on Signal Desktop
Regarding #2, since it's worded somewhat ambiguously, should we read that as wanting to stop targeted attacks in general (I'm thinking specifically of criminal suspects/etc. when a valid warrant exists) or targeted attacks against specific targets (i.e. people being illegitimately targeted like crypto nerds)? As a follow-up, are there any situations in which you think it would be appropriate to give information or the plaintext content of encrypted messages for a specific user to a law enforcement agency?
csandreasen··on Adventures in Twitter Censorship [pdf]
The internet has created a weird environment where repercussions for socially unacceptable speech (even if taken completely out of context) can be dramatically more severe than any harm that was caused by the original speaker. In general, a distasteful tweet or Facebook post shouldn't cost someone their job, make them a target for anonymous threats or make them fear interacting with society at large any more than it would have if the message had just been spoken. There was a good piece on NPR recently that explored a number of examples:

http://www.npr.org/templates/transcript/transcript.php?story...

csandreasen··on Hillary Clinton Is Wrong About Edward Snowden
His passport was revoked the day before he left Hong Kong.[1]. He traveled to Russia on what turned out to be an invalid travel document issued by the Ecuadorian embassy in London [2] (same one that Julian Assange is holed up in).

[1] http://bigstory.ap.org/article/ap-source-nsa-leaker-snowdens...

[2] http://www.theguardian.com/world/2013/jul/02/ecuador-rafael-...

csandreasen··on Fifth Amendment Flowchart
The same site has a good Fourth Amendment flowchart as well:

http://lawcomic.net/guide/?p=2256

For what it's worth, the whole site is a good read for an introduction to American law.

csandreasen··on Dual EC: A Standardized Back Door [pdf]
Dual_EC was the default PRNG for the RSA BSAFE library. The only actual numbers I've seen regarding how popular the library was this researcher's findings[1] in which he did a scan of 21.8 million IP addresses and managed to find 720 servers using it (to be fair, that's a lower bound as there were two implementations of BSAFE and only one was detectable remotely). It was generally easier use a PRNG provided by the OS or use an open source library for free. As a testament to how unpopular Dual_EC was, there was a bug in OpenSSL for years that prevented it from working at all when Dual_EC was enabled, and it wasn't discovered until after Snowden.

[1] http://dualec.org/

Page 1 of 14Next →